RHSA-2022:7457: Moderate: container-tools:rhel8 security, bug fix, and enhancement update
The container-tools module contains tools for working with containers, notably podman, buildah, skopeo, and runc.Security Fix(es): golang: net/http/httputil: panic due to racy read of persistConn after handler panic (CVE-2021-36221) cri-o: memory exhaustion on the node when access to the kube api (CVE-2022-1708) golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191) opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190) buildah: possible information disclosure and modification (CVE-2022-2990) runc: incorrect handling of inheritable capabilities (CVE-2022-29162) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.Additional Changes:For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.7 Release Notes linked from the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.1.0-4.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/cockpit-podmanto a version that resolves this vulnerability.Fixed in 53-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/container-selinuxto a version that resolves this vulnerability.Fixed in 2.189.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1-40.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/netavarkto a version that resolves this vulnerability.Fixed in 1.1.0-6.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/python-podmanto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/udicato a version that resolves this vulnerability.Fixed in 0.2.6-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-dockerto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/python3-podmanto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criu-develto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criu-libsto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/criu-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-gvproxyto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-gvproxy-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656 - Upgrade
Upgrade
redhat/aardvark-dnsto a version that resolves this vulnerability.Fixed in 1.1.0-4.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/buildahto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/buildah-debuginfoto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/buildah-debugsourceto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/buildah-teststo a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/buildah-tests-debuginfoto a version that resolves this vulnerability.Fixed in 1.27.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/conmonto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/conmon-debuginfoto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/conmon-debugsourceto a version that resolves this vulnerability.Fixed in 2.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/containernetworking-pluginsto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/containernetworking-plugins-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.1-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/containers-commonto a version that resolves this vulnerability.Fixed in 1-40.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/critto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criu-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criu-debugsourceto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criu-develto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criu-libsto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/criu-libs-debuginfoto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/crunto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/crun-debuginfoto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/crun-debugsourceto a version that resolves this vulnerability.Fixed in 1.5-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/fuse-overlayfsto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debuginfoto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/fuse-overlayfs-debugsourceto a version that resolves this vulnerability.Fixed in 1.9-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/libslirpto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/libslirp-debuginfoto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/libslirp-debugsourceto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/libslirp-develto a version that resolves this vulnerability.Fixed in 4.4.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/netavarkto a version that resolves this vulnerability.Fixed in 1.1.0-6.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hookto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/oci-seccomp-bpf-hook-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.6-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podmanto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-catatonitto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-catatonit-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-debugsourceto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-gvproxyto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-gvproxy-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-pluginsto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-plugins-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-remoteto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-remote-debuginfoto a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/podman-teststo a version that resolves this vulnerability.Fixed in 4.2.0-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/python3-criuto a version that resolves this vulnerability.Fixed in 3.15-3.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/runcto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/runc-debuginfoto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/runc-debugsourceto a version that resolves this vulnerability.Fixed in 1.1.4-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/skopeoto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/skopeo-debuginfoto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/skopeo-debugsourceto a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/skopeo-teststo a version that resolves this vulnerability.Fixed in 1.9.2-1.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/slirp4netnsto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/slirp4netns-debuginfoto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/slirp4netns-debugsourceto a version that resolves this vulnerability.Fixed in 1.2.0-2.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/toolboxto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/toolbox-debuginfoto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/toolbox-debugsourceto a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656.aa - Upgrade
Upgrade
redhat/toolbox-teststo a version that resolves this vulnerability.Fixed in 0.0.99.3-0.6.module+el8.7.0+16772+33343656.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2022:7457?
The severity of RHSA-2022:7457 is categorized as important.
How do I fix RHSA-2022:7457?
To fix RHSA-2022:7457, update the affected packages to the specified remedial versions provided by Red Hat.
What vulnerabilities are addressed in RHSA-2022:7457?
RHSA-2022:7457 addresses several vulnerabilities, including a panic due to a race condition in golang (CVE-2021-36221) and issues causing memory exhaustion in cri-o.
Which software is affected by RHSA-2022:7457?
The software affected by RHSA-2022:7457 includes container-tools modules like podman, buildah, skopeo, and others.
Is RHSA-2022:7457 applicable to all Red Hat systems?
RHSA-2022:7457 is specific to Red Hat Enterprise Linux 8 and its associated container tools.